CVE-2023-30858

MEDIUM

Denosaurs <0.3.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big payload. The issue has been patched in 0.3.0. As a workaround, avoid using the `replace`, `unemojify`, or `strip` functions.

Scores

CVSS v3 5.3
EPSS 0.0065
EPSS Percentile 70.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (1)
denosaurs/emoji 0.1.0 - 0.3.0
Published Apr 28, 2023
Tracked Since Feb 18, 2026